Splunk Dev

Playbook: How do I turn string into a CSV email attachment?

dulguun
Engager

I've got a string that contains CSV contents. How do I send an email that has an attachment which is made from my string variable?

Labels (1)
0 Karma

marnall
Motivator

If I understand correctly, you would like your string to be converted into a .csv file, and attached to an email sent by SOAR?

This would likely be a multi-step procedure:

1. Use a custom function to write the CSV to a temporary file on disk.

2. Use a custom function to call phantom.vault_add() to convert the temporary file on disk into a CSV in the vault.

3. Pass the ID of the file in the vault to the email action block as the attachment input.


I personally have never gotten the SMTP app to successfully send file attachments, so I would recommend testing sending email with a file already in a vault before starting steps 1 and 2.

dulguun
Engager

Thank you. It worked.

0 Karma
Get Updates on the Splunk Community!

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

[Coming Soon] Splunk Observability Cloud - Enhanced navigation with a modern look and ...

We are excited to introduce our enhanced UI that brings together AppDynamics and Splunk Observability. This is ...